Skip to content

Zero Trust Posture

  • Every network boundary is hostile until proven otherwise.
  • Documentation requires authenticated access even in staging environments.
  • Developers operate from untrusted machines and must avoid storing secrets locally.
ControlStatusNotes
Cloudflare Access for docsPlannedProtects docs.example.com using SSO groups.
MFA on Git hostingActiveRequired for all contributors.
Principle of least privilegeActiveAccess granted per-app or per-project.
Continuous loggingPlannedPending selection of log aggregation tooling.
  1. Finalise SSO provider and group mapping before Cloudflare deployment.
  2. Document Access policies once implemented and link from this page.
  3. Conduct quarterly Zero Trust reviews alongside platform retrospectives.